QuestionQ102

Identify Network Access Control and Security Features

A company is configuring a RADIUS server for wireless-network authentication. It wants to use a certificate with a generic CN across all of its ClearPass RADIUS servers.

What must it ensure so that the certificate is valid for clients managed by an Active Directory domain?

  • A The domain component of the CN must be a domain that the client can verify.
  • B The SAN must include the IP addresses of all RADIUS servers.
  • C The CN must match the exact hostname of each RADIUS server.
Explanation

A shared ClearPass RADIUS certificate may use a generic CN rather than the individual hostname of every RADIUS server. Domain-managed clients must be able to validate the certificate’s name, so the CN’s domain component must be a domain the client can verify. IP-address SAN entries are not required for this purpose.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!